Fake Braintree NuGet Package Skims Credit Cards and Harvests Merchant Credentials
Blog post from Socket
A malicious NuGet package posing as the legitimate Braintree payment gateway client was detected by Socket's AI scanner shortly after its first release on July 3, 2026. The package, named Braintree.Net, mimicked PayPal Braintree's official SDK, intercepting payment card data and exfiltrating Braintree merchant API keys to attacker-controlled infrastructure. It used a similar name and metadata to trick developers, targeting those who mistyped or missearched for the official package. The package included a multi-stage .NET implant, leveraging a dependency called DependencyInjector.Core, which further harvested environment secrets and cloud metadata. Despite the package's high reported downloads, most were artificially inflated, hiding the actual number of affected installations. The malicious package allowed attackers to steal sensitive payment information and merchant credentials, potentially enabling unauthorized transactions. The attack was sophisticated, using techniques like namespace squatting and silent failure paths to avoid detection. Security teams have been notified, and actions have been recommended to mitigate the impact, including removing the package, rotating compromised credentials, and blocking communication with the attacker's infrastructure.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 7 | 2,479 | 445 | 126 | -1% |
| Real-time | 5 | 5,522 | 1,291 | 230 | -4% |
| Kubernetes | 2 | 2,471 | 342 | 109 | +14% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.